And as important: making it impossible or very hard and annoying to export and own your data.
We didn't set out to hide our GDPR requests, we put them behind our Support/Legal button. But we got sued anyway, and we lost. Now we have to have the "delete my data" and "request my data" as part of our main settings list. Result: flooded with requests. People are clicking the buttons just because they are there. For me it's not a big deal, I automate all the requests. But, I still feel like this went too far.
We caught companies making it harder to delete your personal data online
61–70 of 76 posts
Re: We caught companies making it harder to delete your personal data online
#62Here's how the law should work. You own the data you produce, both intentionally (writing, making videos) and unintentionally ("metadata", logs). You have to explicitly give others permission to use that data for any purpose where money exchanges hands (and many where it does not). You can limit or revoke the permission at any time.
Re: We caught companies making it harder to delete your personal data online
#63Here's how the law should work. You own the data you produce, both intentionally (writing, making videos) and unintentionally ("metadata", logs). You have to explicitly give others permission to use that data for any purpose where money exchanges hands (and many where it does not). You can limit or revoke the permission at any time.
This is kind of the case. Under GDPR, the data can only be used for the specific purpose for which is was collected, unless explicit consent is obtained. Terms buried in contracts do not count as consent - a contract has to be clear about the purpose for collecting the data and why it is necessary to fulfil the contract, and using the data for any other purposes is illegal.
However, I doubt it can be extended to training statistical models. LLMs and other models by their nature strip attribution which ironically happens to be the trick they are trying to use to break pretty much all open source licenses.
Re: We caught companies making it harder to delete your personal data online
#64And as important: making it impossible or very hard and annoying to export and own your data.
this will stop being a problem
Re: We caught companies making it harder to delete your personal data online
#65Earlier quoted context omitted.
I have downloaded my data with google takeout dozens of times without a single issue. Speed was very high (maximum possible for my connection) and never had a download error. I’m talking about multi-gigabyte exports of my email and my drive.
I have 900gb in my account and on my 500mbps connection it took forever to download, not because of my speed but because of theirs and it just 'connection failed' at 80% many many many times and asking to relogin. It should be illegal. Not supporting just wget -c (you can use it with a lot of trouble/hacks and it's not reliable which defeats the point) is just clearly done to annoy you into not doing it.
I had to install the drive client on a Windows laptop and download it through that.
Re: We caught companies making it harder to delete your personal data online
#66Earlier quoted context omitted.
> People are clicking the buttons just because they are there. The reasons why they click the buttons are utterly irrelevant to anyone except them. Let them click the buttons. It's their right. > But, I still feel like this went too far. Not far enough. I think data should be a massive liability. It should actively cost you lots of money to know any fact at all about any person anywhere on the planet. In other words,…
At the moment, holding data about someone is not a significant recurrent cost, but it is a liability in the form of a risk that could get you in serious trouble if you get something wrong. However, that particular business risk doesn't tend to be recognised by many many organisations. It should be.
Re: We caught companies making it harder to delete your personal data online
#67Earlier quoted context omitted.
We didn't set out to hide our GDPR requests, we put them behind our Support/Legal button. But we got sued anyway, and we lost. Now we have to have the "delete my data" and "request my data" as part of our main settings list. Result: flooded with requests. People are clicking the buttons just because they are there. For me it's not a big deal, I automate all the requests. But, I still feel like this went too far.
Users have basic bare bones functionality that all applications should support is "too far"? If the user can create and account, they should be able to delete one. One is not harder or further than the other. We just don't view it that way because we're all parasites who feed off the current status quo.
They were objecting to the idea that putting it behind the "support" button is a violation. If true, that's excessive in terms of mandating accessibility.
Re: We caught companies making it harder to delete your personal data online
#68Earlier quoted context omitted.
Users have basic bare bones functionality that all applications should support is "too far"? If the user can create and account, they should be able to delete one. One is not harder or further than the other. We just don't view it that way because we're all parasites who feed off the current status quo.
> Users have basic bare bones functionality that all applications should support is "too far"? They were objecting to the idea that putting it behind the "support" button is a violation. If true, that's excessive in terms of mandating accessibility.
No, requiring actual application functionality isn't too far. For God's sake, just make normal software like a normal person. This should all be very intuitive.
Stop trying to game things, stop trying to maximize conversions and other bullshit metrics, stop trying to implement every dark pattern under the sun and just... Be normal. I promise you will comply without even trying.
And, bonus points, your software will be less shit. I know it doesn't feel that way right now, because most software is shit. You shouldn't aspire to be another turd floating around in the cesspool that is the modern web.
Re: We caught companies making it harder to delete your personal data online
#69Earlier quoted context omitted.
> Users have basic bare bones functionality that all applications should support is "too far"? They were objecting to the idea that putting it behind the "support" button is a violation. If true, that's excessive in terms of mandating accessibility.
I would never file a support ticket to open an account. If you did that, your business would be under by the end of the week. No, requiring actual application functionality isn't too far. For God's sake, just make normal software like a normal person. This should all be very intuitive. Stop trying to game things, stop trying to maximize conversions and other bullshit metrics, stop trying to implement every dark patte…
Well now we're deep into the realm of assumptions.
They said "behind our Support/Legal button" which to me sounds like it probably loads another normal page.
Though a GDPR request basically is a ticket.